CVE-2012-2372 (retired)

The rds_ib_xmit function in net/rds/ib_send.c in the Reliable DatagramSockets (RDS) protocol implementation in the Linux kernel 3.7.4 and earlierallows local users to cause a denial of service (BUG_ON and kernel panic)by establishing an RDS connection with the source IP address equal to theIPoIB interface's own IP address, as demonstrated by rds-ping.

Ubuntu-Description

A flaw was found in the Linux kernel's Reliable Datagram Sockets (RDS)protocol implementation. A local, unprivileged user could use this flaw tocause a denial of service.

jdstrand> linux-armadaxp is maintained by OEM apw> this is claimed fixed by RedHat but I cannot find the fix anywhere, the apw> only reference I did find to the CVE in Fedora implies they have miss apw> tagged the fix for CVE-2012-2373 as 2372: apw> http://permalink.gmane.org/gmane.linux.redhat.fedora.extras.cvs/775892 apw> note the patch is the x86 pmd patch. apw> needs-triage back to -security for lack of a clear direction on a fix (per apw> irc discussions) apw> Looking at the RHEL kernels it appears that this is the fix, though it apw> is not upstream as yet: apw> http://people.canonical.com/~apw/misc/cves/CVE-2012-2372-1.diff kees> https://oss.oracle.com/git/?p=redpatch.git;a=commitdiff;h=c7b6a0a1d8d636852be130fa15fa8be10d4704e8 kees> seems fixed upstream by 18fc25c94eadc52a42c025125af24657a93638c0